2026年9月6日13时53分(UTC),攻击者利用Elements中rangeproof验证缓存的两个关键漏洞对Liquid Network发起攻击1。根据Blockstream的声明,攻击者通过这一漏洞成功绕过验证,使约4000个无实际比特币支持的LBTC被铸造1。随后,攻击者通过SideSwap的peg-out过程将约4000 BTC提取到比特币链上1。
Blockstream在发现安全事件后迅速响应1。于同日18时26分(UTC)协调关闭Liquid桥接节点以阻止进一步资金转移1,并在2026年9月7日01时09分部署了紧急补丁1。完整修复版本Elements v23.3.4于9月9日发布1。
漏洞的根本原因包括:Bug A源于2018年5月的代码变更(Elements PR #335),rangeproof缓存密钥计算中缺少资产承诺和scriptPubKey1;Bug B则是在缺少长度前缀的情况下直接拼接字段导致的字节对齐碰撞1。
经过处理,攻击者已返还3400 BTC,但约602 BTC仍未追回1。
On September 6, 2026 at 13:53 UTC (Liquid block 4,050,336), an attacker exploited critical vulnerabilities in Elements' rangeproof verification cache to mint approximately 4,000 LBTC without corresponding Bitcoin backing 1. The attacker subsequently withdrew roughly 4,000 BTC to the Bitcoin blockchain through SideSwap's peg-out mechanism 1. Upon discovering the breach, Blockstream coordinated the shutdown of Liquid bridge nodes at 18:26 UTC the same day to prevent further fund transfers 1.
The security incident stemmed from two underlying bugs in the codebase 1. Bug A originated from a May 2018 code modification (Elements PR #335) that failed to include asset commitments and scriptPubKey in the rangeproof cache key calculation 1. Bug B resulted from direct field concatenation without length prefixes, creating byte-alignment collisions that bypassed validation 1. Blockstream deployed an emergency patch on September 7, 2026 at 01:09 UTC, followed by the complete fix in Elements v23.3.4 released on September 9 1.
The attacker returned 3,400 BTC following the incident, though approximately 602 BTC remain unrecovered 1.
评论
还没有评论,欢迎留下第一条。